CVE Database
/

CVE-2024-38572

Back to search

CVE-2024-38572

Published: Jun 19, 2024

Modified: May 11, 2026

PUBLISHED

Description

In the Linux kernel, the following vulnerability has been resolved: wifi: ath12k: fix out-of-bound access of qmi_invoke_handler() Currently, there is no terminator entry for ath12k_qmi_msg_handlers hence facing below KASAN warning, ================================================================== BUG: KASAN: global-out-of-bounds in qmi_invoke_handler+0xa4/0x148 Read of size 8 at addr ffffffd00a6428d8 by task kworker/u8:2/1273 CPU: 0 PID: 1273 Comm: kworker/u8:2 Not tainted 5.4.213 #0 Workqueue: qmi_msg_handler qmi_data_ready_work Call trace: dump_backtrace+0x0/0x20c show_stack+0x14/0x1c dump_stack+0xe0/0x138 print_address_description.isra.5+0x30/0x330 __kasan_report+0x16c/0x1bc kasan_report+0xc/0x14 __asan_load8+0xa8/0xb0 qmi_invoke_handler+0xa4/0x148 qmi_handle_message+0x18c/0x1bc qmi_data_ready_work+0x4ec/0x528 process_one_work+0x2c0/0x440 worker_thread+0x324/0x4b8 kthread+0x210/0x228 ret_from_fork+0x10/0x18 The address belongs to the variable: ath12k_mac_mon_status_filter_default+0x4bd8/0xfffffffffffe2300 [ath12k] [...] ================================================================== Add a dummy terminator entry at the end to assist the qmi_invoke_handler() in traversing up to the terminator entry without accessing an out-of-boundary index. Tested-on: QCN9274 hw2.0 PCI WLAN.WBE.1.0.1-00029-QCAHKSWPL_SILICONZ-1

VendorProductVersions

Linux

Linux

affected
d889913205cf7ebda905b1e62c5867ed4e39f6c2 - < 95575de7dede7b1ed3b9718dab9dda97914ea775
affected
d889913205cf7ebda905b1e62c5867ed4e39f6c2 - < b48d40f5840c505b7af700594aa8379eec28e925
affected
d889913205cf7ebda905b1e62c5867ed4e39f6c2 - < a1abdb63628b04855a929850772de97435ed1555
affected
d889913205cf7ebda905b1e62c5867ed4e39f6c2 - < e1bdff48a1bb4a4ac660c19c55a820968c48b3f2

Linux

Linux

affected
6.3
unaffected
0 - < 6.3
unaffected
6.6.33 - <= 6.6.*
unaffected
6.8.12 - <= 6.8.*
unaffected
6.9.3 - <= 6.9.*

+1 more versions

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now